🎙️ In this episode, Craig Birch exposes one of the most dangerous and overlooked misconfigurations in Active Directory: the PasswordNotRequired attribute.
Most AD admins assume password policies apply to all accounts — but this hidden flag allows accounts to exist with blank passwords, silently bypassing domain-wide protections. Attackers know it. Many admins don’t.
🔍 What You’ll Learn:• What the PasswordNotRequired attribute really does
• How it overrides password length, complexity, and history policies
• Which accounts are most at risk (including service and trust accounts)
• Why this setting leads to instant compromise with no brute-force required
• How to identify and fix vulnerable accounts with PowerShell🛠️ PowerShell Spotlight:# Detect accounts with PasswordNotRequired flag set
Get-ADUser -Filter * -Properties userAccountControl |
Where-Object { ($_.userAccountControl -band 0x0020) } |
Select-Object Name, SamAccountName
# Optional: Clear the flag (example)
Set-ADUser username -PasswordNotRequired $false
âś… Use this to find and lock down accounts silently skipping your password policy.
âś… Quick Takeaways:
This setting bypasses all domain password policy enforcement
Common on legacy accounts, service accounts, or through bad provisioning
Easy path to account compromise and privilege escalation
Most AD auditing tools don’t flag it — but attackers know it’s there
Fix it fast using PowerShell and GPO cleanup
💬 Found this helpful? Like, share, or comment. Want a specific AD risk explained in 10 minutes or less? Drop your request below — we’re listening.
📌 Powered by Guardians of the Directory
Stuff You Should Know
If you've ever wanted to know about champagne, satanism, the Stonewall Uprising, chaos theory, LSD, El Nino, true crime and Rosa Parks, then look no further. Josh and Chuck have you covered.
Dateline NBC
Current and classic episodes, featuring compelling true-crime mysteries, powerful documentaries and in-depth investigations. Follow now to get the latest episodes of Dateline NBC completely free, or subscribe to Dateline Premium for ad-free listening and exclusive bonus content: DatelinePremium.com
On Purpose with Jay Shetty
I’m Jay Shetty host of On Purpose the worlds #1 Mental Health podcast and I’m so grateful you found us. I started this podcast 5 years ago to invite you into conversations and workshops that are designed to help make you happier, healthier and more healed. I believe that when you (yes you) feel seen, heard and understood you’re able to deal with relationship struggles, work challenges and life’s ups and downs with more ease and grace. I interview experts, celebrities, thought leaders and athletes so that we can grow our mindset, build better habits and uncover a side of them we’ve never seen before. New episodes every Monday and Friday. Your support means the world to me and I don’t take it for granted — click the follow button and leave a review to help us spread the love with On Purpose. I can’t wait for you to listen to your first or 500th episode!